SSL / TLS
Valid HTTPS · 22ms
x402 discovery
No x402 discovery found
Agent discovery
No agent.json found
llms.txt
HTTP 404 · 287ms
security.txt
Not found · 14ms
CORS headers
No CORS header (OK if server-to-server only) · 30ms
Security headers
0/5 — missing critical: x-content-type-options, strict-transport-security, content-security-policy · 31ms
Response time
337ms avg · 337ms
MCP server
/mcp — 0 tools · 1127ms
API endpoints
2 endpoints found
Error handling
404 JSON response · 406ms
x402 compliance
No x402 payment gates found · 41ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 155ms
Documentation
/docs found · 737ms
robots.txt AI crawlers
No AI crawler directives (GPTBot, ClaudeBot, etc.) · 747ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
No OpenAPI/Swagger spec found
Privacy / GDPR
/privacy found (4129 chars) · 524ms
Status / Health
/status found · 582ms
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
No Travel Rule endpoint or VASP disclosure
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
No DNSSEC — domain is vulnerable to DNS spoofing
CAA Records
No CAA records — any CA can issue certificates
DMARC / SPF
No DMARC or SPF records found
Auth maturity
No authentication detected — open API or check failed
API versioning
/v1
Human oversight
No human oversight / kill switch endpoint (EU AI Act Art. 14)
Terms of Service
/terms found (3843 chars) · 828ms
Content-Type
JSON on 2/2 paths · / missing charset=utf-8, /v1/ missing charset=utf-8
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 3x402 discovery failedNo x402 discovery found
Agent discovery failedNo agent.json found
Warning — 18security.txt needs attentionNot found
CORS headers needs attentionNo CORS header (OK if server-to-server only)
Security headers needs attention0/5 — missing critical: x-content-type-options, strict-transport-security, content-security-policy
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
robots.txt AI crawlers needs attentionNo AI crawler directives (GPTBot, ClaudeBot, etc.)
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec needs attentionNo OpenAPI/Swagger spec found
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
Travel Rule (FATF) needs attentionNo Travel Rule endpoint or VASP disclosure
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionNo DNSSEC — domain is vulnerable to DNS spoofing
CAA Records needs attentionNo CAA records — any CA can issue certificates
DMARC / SPF needs attentionNo DMARC or SPF records found
Auth maturity needs attentionNo authentication detected — open API or check failed
Human oversight needs attentionNo human oversight / kill switch endpoint (EU AI Act Art. 14)
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration